logo

Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting

ID: f5a9ff3a-034a-5c37-a91c-831eefbd6d35

STIX ID: report--f5a9ff3a-034a-5c37-a91c-831eefbd6d35

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-05-31

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Recorded Future attributes a multi-phase espionage campaign to GRU-linked APT28 (BlueDelta) that used HeadLace malware and credential-harvesting pages across Europe—especially targeting Ukrainian defence entities, rail infrastructure, and related organizations—delivered via spear-phishing and a multi-stage redirection infrastructure (GitHub, InfinityFree, webhook.site, mocky.io) with geofencing and exfiltration via compromised Ubiquiti routers; related Turla activity is also noted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.